CISA Exam · 21 min read Updated

CISA Domain 3 Practice Questions: SDLC & Project Management

Rob Pfleghardt

10-year Price Waterhouse alumnus · Founder of VoraPrep · Former CPA (1987–2024) · with the VoraPrep Editorial Team

CISA Domain 3 Practice Questions: SDLC & Project Management

Key Takeaways

  • Exam Domain: 3 - Information Systems Acquisition, Development, and Implementation
  • Exam Weight: 12% of the CISA exam; the exact number of questions varies per test
  • Key Topics: SDLC, Project Management, Agile vs. Waterfall, Testing, Data Conversion, BPR
  • Official Body: ISACA
  • Recommended Study: Varies significantly based on your IT and audit experience
  • Core Skill Tested: Application of auditor judgment and professional skepticism in project scenarios

You’ve memorized the SDLC phases and can recite the Agile manifesto. Then a CISA exam question hits you with a scenario: a project manager wants to skip security testing to meet a deadline. The reason most candidates stumble here isn't forgetting a rule; it’s a failure to apply the auditor's judgment and professional skepticism to weigh the immediate risk against business pressure—a skill Domain 3 relentlessly tests.

Quick answer

Practice questions for CISA Domain 3 are critical because they force you to apply theoretical knowledge to realistic scenarios. They train you to think like an auditor, identify key risks in system development, and make judgment calls on controls, which is the core skill ISACA tests—not just memorization.

Key facts

  • Exam Domain: 3 - Information Systems Acquisition, Development, and Implementation
  • Exam Weight: 12% of the CISA exam; the exact number of questions varies per test
  • Key Topics: SDLC, Project Management, Agile vs. Waterfall, Testing, Data Conversion, BPR
  • Official Body: ISACA
  • Recommended Study: Varies significantly based on your IT and audit experience
  • Core Skill Tested: Application of auditor judgment and professional skepticism in project scenarios

Why Do Most CISA Candidates Struggle with Domain 3 Questions?

Passing the CISA exam, with its 50-55% pass rate, is less about knowing facts and more about applying them. Domain 3 epitomizes this. It's not enough to know the definition of User Acceptance Testing (UAT); you need to know what to recommend when a project team performs UAT with IT staff instead of actual business users.

This is the "judgment gap." Many candidates study to recall information, but the exam demands you evaluate a situation and choose the most appropriate action.

Free 5-Min Diagnostic

Studying for CISA CISA3? Benchmark your score in 5 minutes.

Get an instant weak-spot assessment and a custom 12-week study plan PDF generated for your exam window.

Domain 3 questions are scenario-based. They will give you a situation, a set of constraints (budget, timeline), and a problem. Your job is to identify the most significant risk or the most effective control. Simply reading the CISA Review Manual is passive. Answering high-quality practice questions forces active recall and hones the critical thinking that separates a pass from a fail. VoraPrep's adaptive CISA practice question bank is designed to help you close this gap.

The Auditor's Decision Tree: A Playbook for Domain 3 Scenarios

To think like an examiner, you need a mental framework. For any Domain 3 scenario, use this decision tree to guide your thinking from the facts of the question to the best possible answer. This structured approach prevents you from jumping to a tempting but incorrect answer.

StepAuditor's QuestionExample Application (Scenario: A critical requirement is missed)
1. Identify the Core IssueWhat is the fundamental control weakness or risk described? Is a key control objective not being met?A documented requirement for Segregation of Duties (SoD) is missing from the system design specifications. The control objective of preventing fraudulent transactions is at risk.
2. Assess Materiality & ImpactHow significant is the impact if this isn't fixed? Consider data sensitivity, regulatory impact (e.g., SOX), and potential financial loss.The system is a new payroll application. A lack of SoD could allow a single user to create a ghost employee and approve payments, leading to direct financial fraud. The impact is high.
3. Evaluate the TimingWhere are we in the project lifecycle (e.g., design, testing, post-implementation)?The project is in the design phase, before coding has been completed. The timing is early.
4. Determine the ActionBased on materiality and timing, what is the most appropriate proactive and effective recommendation?Because the impact is high and the timing is early, the best action is to fix the problem now. The formal change management process must be used to re-introduce the SoD requirement into the design and subsequent testing phases.

This structured thinking shows why a post-implementation audit is a valid tool, but a reactive measure. A proactive change request is far better when the problem is caught early.

10 CISA Domain 3 Practice Questions: An Expert Walkthrough (2026)

Apply the auditor's mindset to these 10 questions. For each one, I’ll walk you through the logic, explain the right answer, and dissect the tempting wrong answers—the traps that catch most candidates.

---

Question 1: Data Conversion Integrity

A project team is implementing a new Enterprise Resource Planning (ERP) system. During the data conversion phase, the CISA auditor observes that the team plans to convert historical financial data directly from the legacy system without any reconciliation or validation procedures.

Which of the following is the primary risk associated with this approach?

A. Inadequate user training on the new system's data entry modules.
B. Disruption to ongoing business operations during the conversion.
C. Introduction of inaccurate or corrupt data into the new ERP system.
D. Over-reliance on vendor support for data mapping and transformation.
Expert Insight & Answer:

The key phrase is "without any reconciliation or validation procedures." This points directly to a failure in data integrity controls, a core tenet of data governance.

  • Tempting Wrong Answer (B): Disruption is a risk in any major implementation. However, the scenario describes a specific control weakness, not a general project risk. The lack of validation creates a risk of inaccurate outcomes, which is more specific and severe than general disruption.
  • Why A and D are incorrect: User training (A) is a separate issue from data integrity. Vendor reliance (D) is a risk, but the core problem isn't who is doing the work; it's the lack of verification of the work's output.

The most direct and significant consequence of migrating data without checking it is that errors from the old system (or new errors created during the transfer) will poison the new one. This undermines the entire investment in the ERP and can lead to flawed financial reporting and poor business decisions. This is a classic "garbage in, garbage out" scenario.

Correct Answer: C. Introduction of inaccurate or corrupt data into the new ERP system.

---

Question 2: Auditing Agile vs. Waterfall

An organization is considering adopting an Agile development methodology for its new customer relationship management (CRM) system. The CISA auditor is asked to identify a key characteristic of Agile that would require a different audit approach compared to a traditional Waterfall methodology.

Which characteristic best fits this description?

A. Emphasis on comprehensive documentation at each project phase.
B. Fixed scope and detailed upfront planning.
C. Iterative development cycles and continuous stakeholder feedback.
D. Strict adherence to a sequential, phase-gate project structure.
Expert Insight & Answer:

This question tests your fundamental understanding of Agile versus Waterfall. You need to identify the defining trait of Agile that changes the audit game.

  • Tempting Wrong Answers (A, B, D): These are all hallmarks of the traditional Waterfall model. Candidates who have only a surface-level understanding might get confused. Waterfall demands comprehensive upfront documentation (A), a fixed scope (B), and a strict sequential process (D). Agile is the opposite.

Agile is defined by its iterative nature. Development happens in short cycles ("sprints"), and requirements evolve based on continuous feedback. For an auditor, this means the old model of waiting for a phase to end before reviewing evidence is obsolete. Auditing must become continuous and embedded within the sprints to be effective, often by reviewing controls within the CI/CD pipeline. For more detail, our CISA guide to Agile and DevOps is a great resource.

Correct Answer: C. Iterative development cycles and continuous stakeholder feedback.

---

Question 3: Non-Functional Requirements

During a post-implementation review of a new financial reporting system, the CISA auditor discovers that the system's performance is significantly slower than anticipated, leading to delays in month-end closings. The system met all functional requirements during user acceptance testing (UAT).

What is the most likely cause of this performance issue?

A. Inadequate training provided to end-users.
B. Insufficient system capacity planning.
C. Lack of a formal change management process.
D. Poorly designed user interfaces.
Expert Insight & Answer:

The critical clues are "slower than anticipated" and "met all functional requirements." This tells you the system works, but not at the required scale or speed. This is a failure of non-functional requirements.

  • Tempting Wrong Answer (A): Inadequate user training would lead to user errors or inefficient use of the system, but it wouldn't slow down the system's core processing speed.
  • Why C and D are incorrect: A weak change process (C) is a post-implementation control issue. Poor UI design (D) affects usability, not backend performance.

The issue described is a classic symptom of failed non-functional testing, specifically performance and load testing. This falls under the umbrella of capacity planning. The team likely tested the system's functions but failed to simulate the real-world production load (e.g., thousands of concurrent users, large data volumes). When the system went live, the underlying infrastructure couldn't handle the demand.

Correct Answer: B. Insufficient system capacity planning.

---

Question 4: System Implementation Strategies

An organization is migrating its customer database to a new cloud-based platform. The CISA auditor is reviewing the project plan and notes that the project manager has scheduled the parallel run phase to last for two weeks.

Which of the following is the primary objective of conducting a parallel run during system implementation?

A. To minimize user resistance to the new system.
B. To provide a fallback option if the new system fails catastrophically.
C. To validate the processing accuracy and completeness of the new system.
D. To reduce the overall cost of system implementation.
Expert Insight & Answer:

A parallel run is an expensive but powerful control. You need to know its specific purpose.

  • Tempting Wrong Answer (B): Having a fallback is a benefit of a parallel run, but it's not the objective. The objective is to actively compare the two systems to find errors before you need the fallback. It's a testing strategy, not just a disaster recovery plan.
  • Why A and D are incorrect: User resistance (A) is a change management issue. A parallel run actually increases cost (D) because you are running and staffing two systems at once.

The core purpose of a parallel run is to feed the same live inputs into both the old and new systems and then meticulously compare the outputs. If the old system produces an invoice for $1,250.75 and the new system produces one for $1,250.70, you have found a critical processing error that must be fixed. It is the ultimate form of end-to-end validation.

Correct Answer: C. To validate the processing accuracy and completeness of the new system.

---

Question 5: Software Acquisition and Contract Review

A CISA auditor is reviewing a proposed software acquisition contract. The contract includes provisions for software licensing, maintenance, and support. However, it lacks clear clauses regarding intellectual property (IP) ownership for customizations developed specifically for the organization.

What is the most significant risk to the organization due to this omission?

A. Increased ongoing maintenance costs.
B. Difficulty in integrating the customized software with future systems.
C. Loss of control over proprietary business logic embedded in the customizations.
D. Inability to receive timely vendor support for the base software.
Expert Insight & Answer:

Contract review is a key audit skill. The issue is IP ownership for custom work.

  • Tempting Wrong Answer (A): Maintenance costs might increase for many reasons, but the IP clause is not the direct driver. A vendor could charge high rates even if the organization owns the IP.
  • Why B and D are incorrect: Integration difficulty (B) is a technical issue. Vendor support for the base product (D) is usually covered separately and isn't affected by who owns the customizations.

When an organization pays a vendor to build custom features, that code often contains unique business processes that provide a competitive advantage. If the contract is silent on IP ownership, the default may be that the vendor owns the code they wrote. This means the vendor could sell that same custom logic to a competitor. The organization has paid to develop an asset it does not control. This is a major strategic risk. Mastering this is key; our guide to CISA vendor evaluation can help.

Correct Answer: C. Loss of control over proprietary business logic embedded in the customizations.

---

Question 6: Project Management Trade-offs

An organization is implementing a new payroll system. The project manager proposes to skip the independent security testing phase to accelerate the project timeline.

What is the CISA auditor's primary concern regarding this decision?

A. Increased risk of project cost overruns due to rework.
B. Potential for undetected vulnerabilities leading to data breaches.
C. Negative impact on user adoption and system satisfaction.
D. Delays in obtaining regulatory compliance certifications.
Expert Insight & Answer:

This is a classic "speed vs. security" conflict. The auditor's role is to champion controls and articulate risk with professional skepticism.

  • Tempting Wrong Answer (D): Delays in compliance are a likely outcome of having security flaws, but it's not the root problem. The reason for the delay is the underlying vulnerability. The CISA focuses on the cause, not just the symptom.
  • Why A and C are incorrect: Cost overruns (A) and user adoption (C) are general project concerns, but skipping security testing creates a very specific and severe type of risk.

Independent security testing (like penetration testing) is designed to find flaws that developers, who have an "insider" view, might miss. Skipping it on a payroll system—which contains highly sensitive Personally Identifiable Information (PII)—means vulnerabilities like SQL injection or improper access controls could go live. This creates a direct path for attackers to steal data, leading to breaches, regulatory fines, and reputational damage. This is the most severe and direct risk.

Correct Answer: B. Potential for undetected vulnerabilities leading to data breaches.

---

Question 7: Project Budgeting and Governance

A CISA auditor is reviewing the project budget for a new e-commerce platform. The project manager has allocated a significant portion of the contingency reserve to cover potential scope changes, rather than unexpected technical issues.

What does this allocation primarily indicate about the project planning?

✨ Free Domain Calculator

Calculate Your CISA Study Hours by Domain

See the exact domain-by-domain study breakdown reflecting the 2024 ISACA Job Practice weighting shifts.

Calculate CISA Study Plan →
A. The project is well-funded and unlikely to face financial constraints.
B. The project scope is clearly defined and unlikely to change.
C. There is a high likelihood of scope creep due to poorly defined requirements.
D. The technical team is highly experienced and anticipates no major challenges.
Expert Insight & Answer:

This question asks you to interpret a project management decision. A contingency reserve is for unknown risks. Earmarking it for scope changes makes it a slush fund for a known weakness.

  • Tempting Wrong Answer (D): This is a dangerous assumption. Even the best technical teams face unforeseen issues. A proper contingency would cover things like hardware failures or complex integration bugs, not planned additions.
  • Why A and B are incorrect: The funding level (A) is irrelevant to how the contingency is allocated. The allocation directly contradicts the idea of a clearly defined scope (B).

When a PM plans for scope changes, it's a strong signal that the initial requirements are not solid. They are anticipating that stakeholders will continue to add features and change their minds throughout the project. This is the definition of scope creep. A CISA auditor sees this and immediately recommends strengthening the requirements definition and formal change control processes to prevent uncontrolled budget and schedule expansion.

Correct Answer: C. There is a high likelihood of scope creep due to poorly defined requirements.

---

Question 8: Business Process Reengineering (BPR)

The CISA auditor is evaluating the organization's approach to Business Process Reengineering (BPR) for its order-to-cash process. The organization plans to implement a new workflow system to automate several manual steps.

Which of the following is the most critical success factor for this BPR initiative?

A. Minimizing the cost of the new workflow system.
B. Ensuring seamless data migration from legacy systems.
C. Obtaining strong management support and end-user buy-in.
D. Completing the project within the original timeline.
Expert Insight & Answer:

BPR is fundamentally about changing how people work. The technology is an enabler, not the goal itself.

  • Tempting Wrong Answer (B): Data migration is a critical technical task, but even a perfectly executed technical implementation will fail if users refuse to adopt the new process. BPR success is measured by business outcomes, not just technical perfection.
  • Why A and D are incorrect: Cost (A) and timeline (D) are project management constraints. A project can be on-time and on-budget but still fail if it doesn't achieve the intended business transformation because of human resistance.

BPR initiatives often fail due to organizational resistance to change. Without unwavering support from senior management to champion the vision and enforce the new ways of working, the project will stall. Without buy-in from the end-users who must live with the new process every day, they will find workarounds, revert to old habits, and the promised efficiency gains will never materialize. People are the most critical factor.

Correct Answer: C. Obtaining strong management support and end-user buy-in.

---

Question 9: Testing Strategy and Coverage

An organization is developing a highly customized proprietary trading system. The CISA auditor is reviewing the testing strategy. The development team plans to rely solely on unit testing performed by individual developers.

What is the primary risk associated with this testing strategy?

A. Inadequate documentation of test cases and results.
B. Failure to identify integration issues between different system modules.
C. Difficulty in reproducing defects found during production.
D. Over-reliance on automated testing tools.
Expert Insight & Answer:

This question tests your knowledge of the testing hierarchy. Unit testing is the first level, but it is not sufficient on its own.

  • Tempting Wrong Answer (A): Poor documentation is a risk with any testing, not a specific consequence of relying only on unit tests.
  • Why C and D are incorrect: The issue is a lack of comprehensive testing, which makes production defects more likely, not just harder to reproduce (C). The scenario describes a lack of different testing types, not an over-reliance on tools (D).

Unit tests verify that a single piece of code (a "unit") works correctly in isolation. However, they tell you nothing about whether that unit can communicate correctly with other parts of the system. Integration testing is specifically designed to find errors in the interfaces and data flows between modules. By skipping this, the team is likely to have a system where individual parts work, but the whole thing collapses when they try to work together.

Correct Answer: B. Failure to identify integration issues between different system modules.

---

Question 10: SDLC Process Controls

A CISA auditor is reviewing the System Development Life Cycle (SDLC) documentation for a critical financial application. The auditor notes that the requirement for "segregation of duties (SoD) enforcement within the application" was documented during the requirements phase but is not explicitly addressed in the design specifications or testing plans.

What is the CISA's immediate recommendation?

A. Postpone the system's go-live date until SoD is fully implemented.
B. Document a workaround for SoD enforcement using manual controls.
C. Initiate a formal change request to incorporate SoD into design and testing.
D. Recommend a comprehensive post-implementation audit focused on SoD.
Expert Insight & Answer:

This is a classic "control was dropped" scenario. Your job is to recommend the most effective way to fix the process failure.

  • Tempting Wrong Answer (D): Recommending a post-implementation audit is reactive. It finds the problem after the flawed system is already live, making it much more expensive and disruptive to fix. The auditor's goal is to prevent problems, not just report them later.
  • Why A and B are incorrect: Postponing go-live (A) is a potential outcome, not the immediate action step. Suggesting manual controls (B) is a temporary patch for a permanent system; it's better to build the control into the application itself.

The correct action is to use the organization's formal change management process. A change request is the standard mechanism to re-introduce the missed requirement. This ensures the requirement is properly analyzed, designed, built, and, crucially, tested before the system is deployed. This is the most proactive, cost-effective, and professionally sound recommendation. It fixes the problem at the earliest possible stage.

---

How to Analyze Your Performance on Practice Questions

Getting a question wrong is not a failure; it's a learning opportunity. But to capitalize on it, you need a system. Don't just look at your score. Create a simple log to track your mistakes and reveal patterns.

Your Personalized Mistake Log:
Question #Topic AreaMy AnswerCorrect AnswerWhy I Was Wrong (Knowledge or Judgment?)
Q3Capacity PlanningABJudgment: I focused on the user, not the system's non-functional requirements. I mistook a performance issue for a usability issue.
Q5Contract Review / IPACKnowledge: I didn't fully understand the business risk of unclear IP ownership for custom development.
Q10SDLC ControlsDCJudgment: I chose a reactive audit step (post-implementation) instead of a proactive project control (change request).

After just a few practice sets, this log becomes your personal study guide. It will tell you precisely where to focus your time—whether you need to re-read the section on contract law or practice thinking more proactively. This is the core principle behind the adaptive learning engine at VoraPrep, which automatically identifies and targets your weak areas for you.

What Are the Most Heavily Tested Topics in CISA Domain 3?

While you need to know the entire domain, ISACA returns to several key themes. Focus your energy on mastering these areas where candidates often get tripped up.

Project Governance & Management

ISACA tests your ability to identify the most significant risk in a project plan (scope, budget, timeline) and recommend the appropriate control. This includes understanding how risk frameworks like COBIT or NIST apply. The common trap is focusing on minor issues while missing a major red flag, like a contingency fund earmarked for scope creep.

System Development Methodologies

You must know how the auditor's role and controls must adapt between Waterfall (phase-gate reviews) and Agile/DevOps (continuous, embedded auditing). The trap is thinking Agile means "no controls." The controls are different (e.g., automated testing in a CI/CD pipeline), not absent.

Testing Strategies

Know the specific purpose and control objective of each test type (Unit, Integration, System, UAT, Security) and identify the risk when a stage is skipped. The trap is confusing System Testing (does it meet technical specs?) with UAT (is it fit for business purpose?).

Data Conversion & Governance

ISACA emphasizes the critical importance of data validation, reconciliation, and integrity controls before, during, and after migration. This is part of a broader data governance strategy. The trap is underestimating the risk of "garbage in, garbage out." A perfect new system with corrupt data is useless.

Post-Implementation Review

Understand that the goal is to determine if the system met its business case objectives (benefits realization) and aligns with recovery plans defined in the Business Impact Analysis (BIA). The trap is treating it as a final bug hunt instead of a strategic review of the project's value and lessons learned.

Where Can I Find More High-Quality CISA Domain 3 Questions?

These 10 questions are a starting point. To achieve the fluency and judgment required to pass the CISA exam, you need to work through hundreds of high-quality practice questions.

At VoraPrep, our platform is built for this exact purpose. Our CISA course includes over 2,300 questions covering every topic in the 2026 exam blueprint.

  • Adaptive Learning Engine: VoraPrep doesn't just give you random questions. Our system learns your strengths and weaknesses. It will serve you more questions on topics like "Agile Audit" or "Data Conversion Controls" if it detects you are struggling there, making your study time dramatically more efficient.
  • Detailed, Expert Explanations: Every question comes with a clear explanation that teaches you the "why" behind the answer. We break down why the correct option is best and, just as importantly, why the distractors are wrong—training you to spot those traps on exam day.
  • Vory, Your 24/7 AI Tutor: Confused about the difference between BPR and BPA? Ask Vory. Our AI tutor can provide instant definitions, examples, and clarifications on any CISA concept, anytime.

Don't leave your CISA success to chance. You can explore our exam details and format breakdown to learn more.

⚡ Instant Knowledge Check · 1-Click Test Drive
CISA Domain 5: Protection of Information Assets

When conducting an IS audit of an enterprise cloud infrastructure environment, which of the following identity and access management (IAM) findings represents the GREATEST information security risk?

Frequently asked questions

How many questions from Domain 3 are on the CISA exam? Domain 3 makes up 12% of the CISA exam content outline. While the exam has 150 questions, ISACA states that the exact number of questions per domain can vary slightly from one exam to the next. What is the difference between System Testing and User Acceptance Testing (UAT)? System Testing is performed by the IT/development team to verify that the system meets all specified technical and functional requirements. UAT is performed by business end-users to confirm that the system is fit for its intended business purpose and supports their operational processes. As a CISA, what's my role in a Business Process Reengineering (BPR) project? The CISA's role in a BPR project is to provide assurance over the process. This includes reviewing project governance, assessing risks in the new process design, ensuring adequate controls are built in (not bolted on), and verifying data integrity is maintained during any system changes. Why is a post-implementation review so important? A post-implementation review is critical because it determines whether the project actually delivered the promised business value and met its objectives. It also serves as a lessons-learned exercise to improve future projects, assessing everything from budget adherence to user satisfaction and benefits realization. What are the key risks in data migration? The primary risks are data corruption, data loss, and extended downtime. An auditor should look for strong controls around data extraction, transformation, validation (reconciliation), and a well-tested rollback plan in case of catastrophic failure.

Official resources and references

--- Ready to Pass Your CISA Exam?

You don't have to prepare for the CISA exam alone. VoraPrep is designed to be your personal study coach, with an adaptive learning engine that targets your weaknesses, a 24/7 AI tutor to answer your questions, and thousands of realistic practice questions. We teach you how to think like the examiner so you can walk into your test with confidence.

Visit voraprep.com to get started.

Start Your Free 14-Day Trial at voraprep.com →
RP

About the Author: Rob Pfleghardt

Rob Pfleghardt is the founder of VoraPrep, a comprehensive exam prep platform for the CPA, CMA, EA, CIA, CISA, and CFP exams. A Virginia Tech graduate in Accounting and Finance, Rob began his career at Price Waterhouse, spending a decade in audit and IT consulting. After holding a CPA license for 37 years (1987–2024) and successfully scaling his own enterprise IT consultancy serving the Department of Defense, Rob launched VoraPrep. He now leverages his deep systems architecture background to build the adaptive training technology and curriculum that helps candidates pass their certification exams efficiently.

Connect with Rob on LinkedIn →
Free Diagnostic Assessment

Find your exact CISA weak spots in 10 minutes.

Most candidates fail because they study blindly. Take our free 10-question diagnostic to identify your weakest blueprint topics and receive a custom 12-week study plan PDF generated instantly.

Keep reading

Free 5-min CISA diagnostic + 12-week plan PDF

Start →
CISA 1:1 Prometric Simulator

2,300+ practice questions with instant Socratic feedback